Process Interaction Ratio Analysis for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in detecting malicious behavior due to the vast scale and dynamic nature, which makes it difficult to monitor process behavior effectively, leading to time-consuming and costly incident validation and remediation.

Innovation Solution

An automated system analyzes process interaction ratios (PIR) by calculating the z-score for each process, identifying potentially malicious activities based on deviations from historical means, and confirming malicious behavior by excluding newly introduced computing devices or users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional process monitoring methods are used in enterprise networks, then comprehensive coverage of all processes can be achieved, but the complexity of analyzing and validating malicious incidents increases significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidanalysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and focuses on specific critical parameters (process interaction ratios, PIR z-scores) from the vast amount of process data, rather than analyzing all process attributes. This extraction approach enables effective malicious behavior detection while avoiding the complexity of comprehensive process analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms process monitoring from tracking absolute process counts to analyzing interaction ratios and statistical deviations (z-scores). This parameter transformation converts raw process data into meaningful security indicators, improving detection reliability while reducing analysis complexity.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If manual validation and remediation of malicious incidents are performed, then accurate security assessment can be achieved, but time consumption and costs increase significantly

Engineering Contradiction:
Improveincident validation accuracyVSAvoidremediation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs self-service by automatically detecting, validating, and responding to malicious incidents using process interaction ratio analysis. The automated generation of PIR z-scores and anomaly detection eliminates the need for manual incident validation, reducing both time loss and operational costs while maintaining detection accuracy.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If the network allows dynamic introduction of new devices and users, then network flexibility and scalability are improved, but the difficulty of tracking and monitoring process behavior increases

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidprocess behavior tracking difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The process interaction ratio metric serves multiple functions simultaneously: it tracks process execution patterns, identifies anomalies, adapts to new devices and users, and detects malicious behavior. This universal metric works effectively regardless of network dynamics, maintaining tracking effectiveness while preserving network flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12174947B2Detecting malicious behavior in a network using security analytics by analyzing process interaction ratios
Publication Date: 2024.12.24 FORTINET INC
  • US12174947B2 patent drawing
  • US12174947B2 patent drawing
  • US12174947B2 patent drawing

AI summary

Systems and methods for detecting malicious behavior in a network by analyzing process interaction ratios (PIRs) are provided. According to one embodiment, information regarding historical process activity is maintained. The historical process activity includes information regarding various processes hosted by computing devices of a private network. Information regarding process activity within the private network is received for a current observation period. For each process, for each testing time period of a number of testing time periods within the current observation period, a PIR is determined based on (i) a number of unique computing devices that hosted the process and (ii) a number of unique users that executed the process. A particular process is identified as potentially malicious when a measure of deviation of the PIR of the particular process from a historical PIR mean of the particular process exceeds a pre-defined or configurable threshold during a testing time period.